English
The Internet threat alert status is currently normal. At present, no major epidemics or other serious incidents have been recorded by Kaspersky Lab’s monitoring service. Internet threat level: 1

Atheme "external logout" Denial of Service Vulnerability


Secunia ID

SA51852

Release Date

18 Jan 2013

Criticality

Moderately Critical

Solution Status

Vendor Workaround

Software

Atheme 7.x

Where

From remote

Impact
DoS (Denial of Service)

This includes vulnerabilities ranging from excessive resource consumption (e.g. causing a system to use a lot of memory) to crashing an application or an entire system.

Description

A vulnerability has been reported in Atheme, which can be exploited by malicious people to cause a DoS (Denial of Service).

The vulnerability is caused due to a NULL-pointer dereference error (modules/nickserv/logout.c) when handling an external logout request and can be exploited to crash Atheme IRC services.

The vulnerability is reported in versions 7.0.5.

Solution

Fixed in the source code repository.

Reported by

Reported by the vendor.

Original Advisory

https://github.com/atheme/atheme/commit/1aaa9e8f1d0b0b67b36c2a6318c71beaa7f39194

http://packetstormsecurity.org/files/119635/Atheme-IRC-Services-7.0.5-Denial-Of-Service.html